MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd4969ee0c511b4c650ea6fbd0456fcce978cf2c1c6ab9acc348c287314dc60b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



NanoCore


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bd4969ee0c511b4c650ea6fbd0456fcce978cf2c1c6ab9acc348c287314dc60b
SHA3-384 hash: f1351fe783e5a2e0126c19e70e7626ffcb3af74f47af86c17b1192d88d67bb4f5976f49efd3bce2ba6503a2d4f07091e
SHA1 hash: 8338ff9dae1400c3197276ccf36bf39c4f793ee6
MD5 hash: cc8feb56fa6d01723b11236afbf1d928
humanhash: lima-ack-bakerloo-magazine
File name:RFQ~029873667892~0928763562789.zip
Download: download sample
Signature NanoCore
File size:865'321 bytes
First seen:2020-10-27 10:31:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:P+YLM6LZ4tD8WNbaSxaMM54EHB1qH6bklmGhjNcktfbBH3LvFHd68abMStHY29D4:PzFeuSxaMMu4PO6b+JXjFH9SplDvQ
TLSH 41053312BCF88C1B5E9C66E9D24744C6EF72CC437C96974B3EE1A32AB1413E9027A754
Reporter abuse_ch
Tags:NanoCore zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: viettelidc.com.vn
Sending IP: 103.1.208.228
From: hongquan@paragon.com.vn
Subject: REQUEST FOR QUOTATION.
Attachment: RFQ~029873667892~0928763562789.zip (contains "RFQ~029873667892~0928763562789.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
111
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2020-10-27 01:04:44 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

NanoCore

zip bd4969ee0c511b4c650ea6fbd0456fcce978cf2c1c6ab9acc348c287314dc60b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments